Hi all, I'm hoping someone can solve my problem.
I keep getting webpages popping up all the time.
I've tried the following:
Spybot - Search & Destroy
Ad-Aware SE Personal
CWShredder.exe
McAfee VirusScan
all keep reporting that my computer is infected
and that errors have been fixed but if I run the apps
again then the same problems are reported.
McAfee reports nothing wrong.
below is my HiJackThis report.
thanks
Logfile of HijackThis v1.98.2
Scan saved at 3:54:04 PM, on 2004-12-08
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Network Associates\VirusScan\Avsynmgr.exe
C:\WINNT\system32\crypserv.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\System32\nslsvice.exe
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\ePOAgent\naimas32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\Program Files\Network Associates\VirusScan\VsStat.exe
C:\Program Files\Network Associates\VirusScan\Vshwin32.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\WINNT\system32\tlntsvr.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\Network Associates\VirusScan\Avconsol.exe
C:\WINNT\System32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\NILaunch.exe
C:\ePOAgent\naimag32.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
C:\PROGRA~1\Toolbar\TBPS.exe
C:\PROGRA~1\Toolbar\PIB.exe
C:\Program Files\Common Files\WinTools\WSup.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\HiJack\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50162
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://members.rogers.com/edinardo/bookmarks.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50162
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50162
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 ieautosearch
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Net-It Launcher] C:\WINNT\System32\NILaunch.exe
O4 - HKLM\..\Run: [NaimAgent_UI] C:\ePOAgent\naimag32.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\winnt\system32\calsp.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {08288600-E9D9-11D1-9C84-006008319186} (VanTFind.VanTFindCtrl) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\vantfind.cab
O16 - DPF: {0CBD083F-B6B3-11D0-AD20-0060976EA210} (DropBox Control) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\vandropbox.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS...er.cab31267.cab
O16 - DPF: {3CA57BA4-0497-11D2-A955-006008936C61} (VanRollupGraph.VanRollupGraphCtrl) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\VanRollup.CAB
O16 - DPF: {4B8351A1-7046-11D2-AA27-006008936C61} (VanForecastGraph.VanForecastGraphCtrl) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\VanFCast.CAB
O16 - DPF: {6262D3A0-531B-11CF-91F6-C2863C385E30} (Microsoft FlexGrid Control, version 6.0) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\msflxgrd.cab
O16 - DPF: {6313ACD5-705C-11D3-8ACA-004F4E002623} (EuroSup.EuroNation) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\EuroSup.cab
O16 - DPF: {6D852581-7F1A-11D2-9CAB-006008319186} (VanColorPickProj.VanColorPick) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\VanColorPick.CAB
O16 - DPF: {72D78A82-8953-67B4-4792-9C034B139753} - ms-its:mhtml:file://c:\nosuch.mht!http://www.foxik.com/chm/files.chm::/file.exe
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {99AC51A7-BEFF-11D1-B5B1-00A024CD30C6} (VanFind.VanFindCtrl) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\VANFIND.cab
O16 - DPF: {A6928F2E-DDEF-11D1-804D-006097F95635} (vanStageTask.van_stage_task_ctl) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\vanStageTask.CAB
O16 - DPF: {A72C9639-8D4D-11D2-B52E-00105A986075} (prjVantiveFontPicker.ctlFontPicker) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\VantiveFontPicker.CAB
O16 - DPF: {ADCBFFBC-DB3F-11D2-AADF-006008936C61} (VanGrid.VanGridCtrl) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\vangrid.cab
O16 - DPF: {B2E0C2EA-A543-11CF-BC8C-207402C10627} (GMS Angular Gauge ActiveX Control) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\AGaugeM.cab
O16 - DPF: {B8958DE0-BAC9-101C-933E-0000C005958C} (FarPoint DateTime Control) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\edt32x20.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {B9FDDE3F-28E2-11D2-B461-006008936ABD} (vanChevron.van_chevron_ctl) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\vanChevron.CAB
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab
O16 - DPF: {C6CCA9AF-2B4E-11D1-9B21-0080C79EFE90} (VanPallet.VanPalletCtrl) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\VanPallet.CAB
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab31267.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://bridgestraining.webex.com/client/v_...ing/ieatgpc.cab
O16 - DPF: {E0DB982A-E986-11D0-B2F8-00A0247B9D10} (VanViewer.VanViewerCrtl) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\VanViewer.CAB
O16 - DPF: {EB52CF7B-3917-11CE-80FB-0000C0C14E92} (SSDateCombo Control) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\SSCALA32.cab
O16 - DPF: {EC9B6CDE-C5BF-11D2-820B-00A024CD30C6} (VanLiteralDLL.VanLiteral) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\VanLiteralDLL.CAB
O16 - DPF: {F39FD815-E9C3-11D1-9C83-006008319186} (VanTree.VanTreeCtrl) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\VanTree.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab
O16 - DPF: {FF1DACCD-3047-11D1-8028-00A024CA8C68} (VanPipelineGraph.VanPipelineGraphCtrl) - file://C:\DOCUME~1\ADMINI~1.CAR\LOCALS~1\Temp\VanPipeline.CAB
O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll